During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?
Verifying written permission is necessary because CDNs are external service providers. Testing them without authorization is a violation of the Rules of Engagement. Obtaining documented consent ensures that the testing activity is permitted under the provider's acceptable use policy, mitigating legal risks for both the tester and the client.
Why this answer
Testing a CDN often involves third-party infrastructure that falls outside the client's direct control. Testing these assets without explicit authorization from the CDN provider can trigger automated DDoS mitigations or legal disputes. Confirming whether the CDN is in-scope prevents accidental service disruption and potential contractual violations, ensuring the pentest methodology adheres to legal boundaries and professional standards regarding third-party service provider interaction.
Exam trap
Candidates often assume cloud assets owned by the client can be freely scanned without checking if third-party CDN providers require explicit authorization.